TYPO3.Jumpurl.File.Disclosure

description-logoDescription

This indicates a potential file-disclosure vulnerability in Typo3.
The vulnerability is within the jumpUrl mechanism of Typo3. Remote attackers may exploit this to read arbitrary files.

affected-products-logoAffected Products

TYPO3 versions 3.3.x, 3.5.x, 3.6.x, 3.7.x, 3.8.x, 4.0 to 4.0.11, 4.1.0 to 4.1.9, 4.2.0 to 4.2.5, 4.3alpha1

Impact logoImpact

Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.

recomended-action-logoRecommended Actions

Upgrade to the newest Typo3 versions.
http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-002/

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Status Detail
2023-08-01 25.612
Modified
Name:Typo3.
Jumpurl.
File.
Disclosure:TYPO3.
Jumpurl.
File.
Disclosure